Rise Zap
affifnliolaibgojgliojpifcebcopla
Risk Score
4.63
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own generic policy — not scoped to this extension, yet admits data collection and third-party sharing (+10 privacy).
- Brand impersonation: extension claims WhatsApp integration, developer domain is gmail.com, not Meta/WhatsApp.
- Free-webmail developer (gmail.com) with no verified business website raises accountability concerns.
- Content script runs on web.whatsapp.com with no CSP — two innerHTML DOM-XSS sinks present; WhatsApp session data at risk.
- 3 installs with non-trivial host access to WhatsApp Web and a Supabase backend — tail attack surface concern.
Evidence
- privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — not extension-scoped; data_collection=true, third_party_sharing=true.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true; developer domain gmail.com, not confirmed owner of WhatsApp brand.
- free_webmail_developer store Developer email ajudarisecommunity@gmail.com — free webmail, no verified business site.
- dom_xss_no_csp crx Two innerHTML sinks in content scripts running on web.whatsapp.com; csp_present=false increases XSS risk.
- supabase_backend_host manifest host_permissions include txnhtcyjzohxkfwdfrvh.supabase.co — unverifiable third-party DB with user data access.
- very_low_install_count store Only 3 installs; extension is essentially untested by community, reputation signals absent.
- no_csp_mv3 manifest content_security_policy=null on MV3; no explicit CSP hardening despite DOM-sink findings.
- wayback_no_snapshot api No Wayback Machine snapshot; developer domain history unverifiable.
Permissions Breakdown
- storage low Stores local extension state; low risk.
- alarms low Schedules periodic tasks; low risk.
- https://web.whatsapp.com/* medium Content-script and request access to WhatsApp Web — can read/send messages on user's behalf.
- https://txnhtcyjzohxkfwdfrvh.supabase.co/* medium Direct access to a Supabase backend; data may be exfiltrated to this third-party DB.
- https://risezap.online/* medium Access to developer's own domain; risk depends on trustworthiness of that domain.
Pillar Scores
Permissions2.30
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 05:13
Listing SHA
3c110e445d43…
Force block
— not fired
Score recovered
no
Elapsed
—